Your Logo
Hello World, I’m
Hello

Ermiyas Tilahun

I Help Organizations Manage Cyber Risk and Stay Compliant by bridging Governance with Hands-on Cybersecurity Expertise in VA/PT, SIEM & Security Monitoring

GRC | NIST | ISO 27001 | PCI DSS | SOC2 | Security Services

About me

Seasoned Cybersecurity GRC professional with 10+ years in banking and finance. As Manager of IT Security Risk Assessment & Change Management, I lead enterprise risk management, security assessments, compliance, and change governance. Expert in implementing global frameworks including ISO 27001, NIST, COBIT, SOC 2, SWIFT, and PCI DSS. I blend deep technical skills in vulnerability assessment, penetration testing, SIEM, and ethical hacking with strong governance and leadership to build resilient, secure banking environments. Passionate about turning risks into robust security postures.

M.A. in Project Management       |       B.Sc. in Computer Science

Skills and Tools

Governance & Compliance


ISO 27001 (ISMS Implementation & Audit Support)

PCI DSS Compliance

Security Policies & Procedures Development

Internal & External Audit Coordination

Control Design & Implementation

Regulatory Compliance Mapping

Risk Management & Assessment


Risk Assessment & Risk Register Management

Risk Treatment Planning

Business Impact Analysis (BIA)

Third-Party Risk Management

Vulnerability Assessment (VA)

Penetration Testing (PT) Coordination

Offensive Security & Testing


Ethical Hacking Methodologies

Web Application Security Testing

Burp Suite (Proxy, Scanner, Repeater)

OWASP Top 10 Testing

Reconnaissance & Enumeration

Basic Exploitation Techniques

Security Architecture & Engineering


Secure System Design Principles

Access Control & Identity Management

Network Security Concepts

Secure Configuration & Hardening

API Security Basics

Secure SDLC Awareness

Audit, Monitoring & Reporting


Security Audits & Gap Analysis

Control Effectiveness Review

Compliance Reporting

KPI / KRI Definition & Tracking

Log Review & Basic Monitoring

Documentation & Evidence Management

Security Awareness & Training


Security Awareness Programs

Phishing Awareness & Simulation Support

Policy Awareness Campaigns

End-User Training Materials

Social Engineering Risk Education

Compliance Specific Awarness Training

Burpsuite
kali Linux
Postman
Wireshark
Metasploit
OWASP ZAP
Redhat
Linux
Burpsuite
kali Linux
Postman
Wireshark
Metasploit
OWASP ZAP
Redhat
Linux

Certifications and Achievments

Page 1 / 1

Experience

Experienced in cybersecurity for over a decade, with hands-on expertise across technical, non-technical, and managerial roles. My background spans SOC operations, threat detection, incident response, and security assessments, alongside leadership responsibilities in coordinating teams and security initiatives. These represent my most recent and key professional experiences. For a complete and formal overview of my career history, please refer to my official resume.

2024 - Present

GRC Manager

Bank of Abyssinia

Leading governance, risk, and compliance initiatives by defining security policies, managing risk assessments, and ensuring alignment with ISO 27001, PCI DSS, and internal security standards across the organization.

GRCISO 27001PCI DSSRisk ManagementCompliance
2022 - 2024

Senior IT Security Assessment Officer

Bank of Abyssinia

Conducting security assessments, vulnerability evaluations, and compliance reviews, while promoting security awareness to identify risks and strengthen security posture.

Security AssessmentVA/PTRisk AnalysisISO 27001Compliance
2019 - 2022

It Security Assessment Officer

Bank of Abyssinia

Performing security assessments, vulnerability evaluations, and compliance checks, while supporting security awareness efforts to identify risks and improve overall security posture.

Risk AssessmentVA/PTRisk AnalysisComplianceAwareness
2018 - 2019

Senior Information Technology Security Expert

InfoSec Labs

Leading advanced security engineering, threat detection, and incident response, while promoting security awareness to strengthen system resilience and overall security posture.

Security EngineeringThreat DetectionIncident ResponseSIEM

My Works

A collection of my cybersecurity projects, certifications, GitHub contributions, and technical implementations in GRC, SIEM, VA/PT, and security engineering.

🚧 This section will be added soon 🚧

Testimonials

Biruk Worku Kote

- Director at Abay Bank

I worked with Ermiyas Tilahun as his supervisor and continued to observe his growth after. He has strong technical skills in cybersecurity, system design, and full-stack development, with a clear strength in security-focused problem solving. He is highly analytical, detail-oriented, and consistently delivers reliable solutions. He is also adaptable, collaborative, and dependable, making him a strong fit for advanced technical roles.

Ermiyas Gera Fiseha

- Red Team Manager at Bank of Abyssinia

I’ve worked closely with Ermiyas Tilahun and confidently recommend him as a highly skilled cybersecurity and full-stack professional. He combines strong technical expertise in security engineering and offensive security with a structured, detail-oriented mindset. He is reliable, adaptable, and performs well under pressure. I believe he can excel in any advanced engineering or cybersecurity role.

Tewodros Mengistu Yimer

- Information Sytems Security Director at Amhara Bank

I worked alongside Ermiyas while leading the SOC, as he was part of the GRC team. He brings exceptional technical expertise in security assessments, risk, and compliance, consistently turning complex challenges into practical, high-impact solutions. Even after I moved on, we’ve remained in close contact, and he continues to support and collaborate with me—demonstrating both his reliability and strong professional character.

Jane Doe

- CEO at Tech Innovators

Ermiyas consistently demonstrates a rare combination of deep technical expertise and practical problem-solving ability. He approaches challenges with a structured mindset, pays strong attention to detail, and maintains a high standard in everything he delivers. Beyond his technical strengths, he is highly collaborative, adaptable, and reliable under pressure—qualities that are essential in modern security environments. Ermiyas consistently demonstrates a rare combination of deep technical skkssl.

Establish a Secure Connection

Have a project, opportunity, or just want to say hi? Let’s connect.

AVAILABLE FOR OPPORTUNITIES

Open to freelance, full-time and collaborations.

📞 +251 910 72 3360
📍 Addis Ababa, Ethiopia
Prefered: Email or LinkedIn

SECURE MESSAGE TERMINAL

© 2026 Ermiyas.com | All right reserved.